[-] drspod@lemmy.ml 18 points 1 week ago

There's something important missing from this article:

Eventually, that same USB drive is inserted into an air-gapped computer, allowing GoldenDealer to install GoldenHowl (a backdoor) and GoldenRobo (a file stealer) onto these isolated systems.

Why is an airgapped machine running executable code from a USB drive? Is there some OS-level vulnerability being exploited?

The original writeup says the following:

It is probable that this unknown component finds the last modified directory on the USB drive, hides it, and renames itself with the name of this directory, which is done by JackalWorm. We also believe that the component uses a folder icon, to entice the user to run it when the USB drive is inserted in an air-gapped system

So we have airgapped machines that rely on users to click icons in a graphical file manager to move data from USB drives. This is a complete failure of security procedure. If you have systems that need to be airgapped then you also need the corresponding procedures for use of those systems to prevent this kind of compromise.

[-] drspod@lemmy.ml 19 points 2 weeks ago

they sure aren’t disproving how woke they are

Why do you think that they need to be doing this?

[-] drspod@lemmy.ml 20 points 1 month ago

I used Ubuntu from version 8.04 to 18.04 and not once did I have a successful upgrade between major versions. There is always something that gets broken to the point that a reinstall is necessary.

[-] drspod@lemmy.ml 21 points 1 month ago

Can't wait to read about it telling someone to put glue on pizza.

[-] drspod@lemmy.ml 20 points 1 month ago

I love that the local translation feature is getting regular small updates to make it more useable. It's a great feature.

[-] drspod@lemmy.ml 21 points 2 months ago

This is huge news. Great work to the contributors involved in making this happen.

[-] drspod@lemmy.ml 21 points 2 months ago* (last edited 2 months ago)

As soon as Linus starts talking about something that you actually know about, you realise that he is bullshitting you, and it immediately calls into question everything that you've heard him say about subjects that you're not an expert in.

I had this realization about LTT years ago, but it's a known phenomenon in journalism (the Gell-Mann amnesia effect) and seems to be even more common in YouTube journalism since the barrier to entry of publishing video is so much lower than publishing in print.

[-] drspod@lemmy.ml 18 points 1 year ago

The key thing to know is that a client can do an HTTP HEAD request to get just the Content-Length of the file, and then perform GET requests with the Range request header to fetch a specific chunk of a file.

This mechanism was introduced in HTTP 1.1 (byte-serving).

[-] drspod@lemmy.ml 19 points 1 year ago* (last edited 1 year ago)

Tencent Games strategic advisor Shawn Layden ...

Non-endemic companies such as Google and Amazon are among the biggest threats to the games industry.

That's according to former PlayStation boss Shawn Layden, who shared his thoughts on the future of games during the keynote at last week's GamesIndustry.biz Investment Summit in Seattle.

The irony is palpable throughout this entire article.

[-] drspod@lemmy.ml 22 points 1 year ago

Yeah. RISC is good.

view more: ‹ prev next ›

drspod

joined 2 years ago